Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability
WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability
WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability
GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2
zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
D-Link DNS-320 multi_uploadify.php unrestricted upload
D-Link DNS-320 multi_uploadify.php unrestricted upload
D-Link DNS-320 save_ajax.php unrestricted upload
D-Link DNS-320 uploadify.php unrestricted upload
D-Link DNS-320 uploadify.php unrestricted upload
D-Link DNS-320 upload.php unrestricted upload
Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload
FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0
HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context
Showing 1 - 20 of 1,000+ results